Authentication Bypass in OpenStack Zaqar by OpenStack Foundation
CVE-2026-66139
4.8MEDIUM
What is CVE-2026-66139?
An authentication bypass vulnerability exists in OpenStack Zaqar versions up to 22.0.0, allowing attackers to gain unauthorized access by exploiting an EXTRA-SPEC header if a known UUID is provided. This flaw could potentially allow malicious entities to bypass authentication mechanisms, posing significant risks to the security of the OpenStack services reliant on Zaqar.
Affected Version(s)
Zaqar 12.0.0 < 20.1.1
Zaqar 21.0.0
Zaqar 22.0.0
